Skip to content

<<< Hide Navigation Hide TOC >>>

UNC5330 (c5ea778c-df2f-4c63-b401-dded9cb2419c)

UNC5330 is a suspected China-nexus espionage actor. UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM. UNC5330 has employed Windows Management Instrumentation (WMI) to perform reconnaissance, move laterally, manipulate registry entries, and establish persistence. Mandiant observed UNC5330 operating a server since Dec. 6, 2021, which the group used as a GOST proxy to help facilitate malicious tool deployment to endpoints. The default certificate for GOST proxy was observed from Sept. 1, 2022 through Jan. 1, 2024. UNC5330 also attempted to download Fast Reverse Proxy (FRP) from this server on Feb. 3, 2024, from a compromised Ivanti Connect Secure device. Given the SSH key reuse in conjunction with the temporal proximity of these events, Mandiant assesses with moderate confidence UNC5330 has been operating through this server since at least 2021.

Galaxy ColorsBackdoorThreat Act...Tool
Rows: 4
Loading extensions...
Collapse filters
Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
<, <=, >, >=, =, *, !, {, }, ||,&&, [empty], [nonempty], rgx:
Learn more

TableFilter v0.7.2

https://www.tablefilter.com/
©2015-2025 Max Guglielmi
?
Cluster A Galaxy A Cluster B Galaxy B Level
PHANTOMNET (f97ea150-a727-4d47-823a-41de07a43ea9) Backdoor UNC5330 (c5ea778c-df2f-4c63-b401-dded9cb2419c) Threat Actor 1
TONERJAM (540b3e66-edbf-40ee-ae05-474b27c1ff40) Tool UNC5330 (c5ea778c-df2f-4c63-b401-dded9cb2419c) Threat Actor 1
UNC5330 (c5ea778c-df2f-4c63-b401-dded9cb2419c) Threat Actor GOST (c9f26173-ba82-4ed2-adbd-e2e07f582f31) Tool 1
PHANTOMNET (f97ea150-a727-4d47-823a-41de07a43ea9) Backdoor TONERJAM (540b3e66-edbf-40ee-ae05-474b27c1ff40) Tool 2